Risk-informed Authorization for Non-Program Users Function
Parent: GR
Description
The mission should use only verified identities when provisioning authenticators to organizational users and processes acting on behalf of users.
Mapped SPARTA techniques
2 techniques
The practice requires verified identity before provisioning authenticators to users acting on the mission's behalf, which governs how an academic or international collaborator is admitted without constraining what they do once admitted.
Vendor access is provisioned under the same identity-verification obligation, which governs the admission step of the trusted relationship the technique abuses.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Crosswalks to 2 in NIST SP 800-53 Rev. 5
Cite as SafeMode Space, nasa-bpg GR-AUTH-02.